Skip to main content

Critical Vulnerability in Junos OS

A critical vulnerability in J-Web of Junos OS SRX Series and EX Series could allow pre-authentication remote code execution

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

A critical vulnerability in J-Web of Junos OS SRX Series and EX Series could allow pre-authentication remote code execution


Threat details

Introduction

An out-of-bounds write vulnerability in J-Web of Juniper Networks Junos OS SRX Series and EX Series allows an unauthenticated, network-based attacker to cause a denial-of-service (DoS), or remote code execution (RCE) and obtain root privileges on an affected device. The vulnerability, assigned CVE-2024-21591, has a CVSSv3 score of 9.8 and is caused by use of an insecure function allowing an attacker to overwrite arbitrary memory.

Proof-of-concept available for CVE-2024-21591

A proof-of-concept for the exploitation of CVE-2024-21591 has been publicly released. Exploitation of this vulnerability is more likely.


Threat updates

Date Update
13 Feb 2024 Proof-of-concept available for CVE-2024-21591

Proof-of-concept publicly available for exploitation of CVE-2024-21591

The cyber alert has been updated to reflect this change.


Remediation advice

Affected organisations are encouraged to review the Juniper Junos OS Security Bulletin and apply any relevant updates.



Last edited: 13 February 2024 3:15 pm